Security Teams Need to Understand How Software Actually Gets Shipped
Finding vulnerabilities still matters. Preventing weak code, dependencies and configurations from reaching production requires a different set of skills.

A security professional reviews an application and finds a vulnerability. The development team fixes it. Everyone moves on.
Then the same type of problem appears in the next release.
That’s usually a clue that the weakness lives somewhere deeper than one piece of code. Perhaps the build process accepts an unsafe dependency. A security check happens too late. A container configuration is copied from an old template. Developers receive feedback after the release is practically finished.
NIST’s National Cybersecurity Center of Excellence is putting more attention on exactly this part of software security. Its updated DevSecOps resources, published on 24 September, include CI/CD pipeline automation, containerized application deployment and functional scenarios showing security activities throughout the software development lifecycle. NIST
The workforce implication is straightforward. Application security professionals increasingly need to understand how software moves from a developer’s machine into production.
Security Work Is Moving Into the Pipeline
Traditional security testing can happen near the end of development. DevSecOps pushes security activities into the processes developers already use to build, test and deploy software.
That requires people who can work across disciplines.
Useful DevSecOps capability includes understanding:
- How source code moves through a CI/CD pipeline
- Where automated security testing should occur
- How dependencies and software components are tracked
- How containers and deployment configurations are built
- Which findings should block a release and which require review
- How credentials and secrets are handled during builds
- How security feedback reaches developers quickly enough to be useful
NIST’s DevSecOps project maps practices from its Secure Software Development Framework into a reference model intended to show how security tasks can operate within modern development pipelines. NCCoE
NICE has also added DevSecOps as a formal competency area in version 2.2.0 of its cybersecurity workforce framework. NIST
That puts software delivery knowledge squarely inside cybersecurity skills development.
Automation Still Needs Judgment
A pipeline can run dozens of checks before software reaches production. That doesn’t mean every alert deserves to stop a release.
Someone still has to understand context.
A vulnerable component might be unreachable in the application. Another finding may expose an internet-facing function handling sensitive information. A failed configuration test could indicate a minor deviation or a serious exposure.
The security professional needs enough development knowledge to discuss the finding with engineers and enough risk judgment to decide what deserves immediate attention.
Otherwise, automation simply produces security findings at machine speed. The backlog will be delighted.
Train With the Pipeline Running
DevSecOps is difficult to learn from diagrams alone.
A stronger exercise gives participants source code, a CI/CD pipeline, automated tests, container builds and a deployment environment. Introduce an insecure dependency or configuration, then ask learners to identify where the control should catch it and what should happen next.
Let them change the pipeline, run another build and see the result.
That practical loop fits the learning approach at ITSEC Cyber & AI Academy. Cybersecurity professionals can build technical capability around application security, testing and secure delivery by working with systems that behave like the environments they’ll encounter on the job.
A vulnerability report tells a team what went wrong once.
DevSecOps skills help them change the process that allowed it through.
Explore hands-on cybersecurity and AI learning at ITSEC Cyber & AI Academy.
References
- NIST NCCoE, “New NIST NCCoE Resources on DevSecOps and October 28 Webinar on Agentic AI,” 24 September 2026
- NIST NCCoE, “Secure Software Development, Security, and Operations (DevSecOps) Practices Live Document,” 24 March 2026, updated on a rolling basis
- NIST NICE, “NICE Releases NICE Framework Components v2.2.0,” 28 April 2026
.png)


